A multi-protocol data security forwarding method and system for industrial gateway
By building the control plane and data plane of the SDN network in the industrial gateway, and enabling visualized configuration and real-time topology control, the security and operational efficiency issues of traditional industrial gateways are solved, and secure and controllable multi-protocol data forwarding and centralized management are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN GUANGLIANZHITONG TECH CO LTD
- Filing Date
- 2026-01-15
- Publication Date
- 2026-08-04
AI Technical Summary
In industrial IoT scenarios, traditional industrial gateways have weak security mechanisms, lack encryption and authentication mechanisms, and data transmission is easily eavesdropped or tampered with. Forwarding strategies are rigid and difficult to adjust, and configuration management is scattered, resulting in low operation and maintenance efficiency.
By using SDN network technology to build the control plane and data plane of industrial gateways, visualized configuration management is achieved, topology nodes are allocated, a real-time topology control network is built, secure forwarding paths are configured, and intelligent scheduling is performed based on real-time traffic. A synchronization network for gateway devices is established to achieve collaborative operation and maintenance.
It enables secure and controllable data forwarding in multi-protocol industrial gateways, supports centralized device management, and improves operation and maintenance efficiency as well as the security and flexibility of data transmission.
Smart Images

Figure CN121814589B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security forwarding technology, specifically to a multi-protocol data security forwarding method and system for industrial gateways. Background Technology
[0002] In industrial IoT scenarios, field devices often communicate using various industrial protocols (such as Modbus, OPC UA, Profinet, MQTT, etc.). Traditional industrial gateways mostly use protocol conversion to forward data, but this has the following problems: Weak security mechanisms, with industrial protocols generally lacking encryption and authentication mechanisms, make data transmission vulnerable to eavesdropping or tampering; rigid forwarding strategies make it difficult to adjust forwarding paths based on real-time traffic demands; and decentralized configuration management, with gateway devices widely distributed, makes policy updates and configuration synchronization difficult, resulting in low operational efficiency.
[0003] Therefore, there is an urgent need for a multi-protocol industrial gateway data forwarding method that can achieve secure and controllable forwarding and support centralized device management. Summary of the Invention
[0004] The purpose of this invention is to provide a multi-protocol data security forwarding method and system for industrial gateways to address the shortcomings in the prior art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a multi-protocol data security forwarding method for industrial gateways, comprising the following steps: Step S1: Construct the control plane and data plane for operating the industrial gateway using SDN network technology, and perform corresponding visual configuration management for the control plane and data plane. Step S2: The control plane performs protocol-related processing on the data packets of the industrial gateway at different time periods, allocates a topology node corresponding to the data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; Step S3: Configure a secure forwarding path for data packets at each topology node in the data plane, and perform intelligent traffic scheduling on the secure forwarding path based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. Step S4: Establish a gateway device synchronization network and perform collaborative operation and maintenance on industrial gateways with different protocols based on the gateway device synchronization network.
[0006] In a preferred embodiment, the process of constructing the control plane and data plane for operating an industrial gateway using SDN network technology includes: An SDN controller is deployed using SDN network technology. The SDN controller communicates with several industrial gateways, divides the communication coverage area corresponding to several industrial gateways, and sets up regional proxy interfaces. Create a private authorized interface for each industrial gateway, establish an authentication path between the regional agent interface and the private authorized interface under the same communication coverage area, and connect several private authorized interfaces to the same regional agent interface; Each sub-architecture for decision management and data forwarding is obtained through the authentication path, and corresponding sub-control planes and sub-data planes are constructed respectively. All sub-control planes and sub-data planes are arranged according to their distribution locations in the deployment area to construct control planes and data planes for operating all industrial gateways.
[0007] In a preferred embodiment, the process of performing corresponding visual configuration management for the control plane and the data plane includes: Several visual drag points and corresponding interactive containers are set on the control plane. Within the interactive containers, devices related to the industrial gateway can be added, deleted, and moved. Each visual drag point corresponds to a sub-control plane. Each interactive container records the parameter configuration of its own industrial gateway and synchronizes it to other interactive containers for configuration synchronization of other industrial gateways; The data plane is divided based on the sub-data plane to obtain several visualization management points. The sub-data plane and the sub-control plane are aligned in position to establish data communication between the visualization management points and the visualization drag points. When forwarding data for each industrial gateway, the real-time traffic of each industrial gateway is counted and included in its respective interaction container in the control plane. Different interaction containers synchronize the traffic changes between several industrial gateways.
[0008] In a preferred embodiment, the process of the control plane performing protocol-related processing on data packets from the industrial gateway at different time periods includes: All data that each industrial gateway needs to transmit is encapsulated into a single data packet; Based on the time window of the data packet encapsulation period, the data packet is sliced according to the time window and processed into several time-series slice data. The time-series slice data under the same time window are integrated into a data queue. Set the source target and linked target in each data queue, establish a message component between the linked target and the source target, and complete the data packet protocol-related processing based on the message component to complete the corresponding data transmission.
[0009] In a preferred embodiment, the process of allocating a topology node corresponding to a data packet on the control plane and constructing a real-time topology control network under the current control plane based on the topology node includes: Create a network access request for a data packet, set up several network nodes, allocate a certain amount of network resources to each network node, and determine whether each network access request is compatible with the network resources of all network nodes in the adjacent ring position. The decision on whether to identify the corresponding network node as a topology node is based on the judgment result. After each data packet has completed its allocation to the topology nodes on the control plane, a topology path is constructed between the topology nodes at each adjacent location to connect the topology nodes at different locations, thus constructing the topology control network. Whenever a new topology node is generated and assigned to the control plane, a topology path is established between the new topology node and the existing topology control network and used as an update to obtain the real-time topology control network under the current control plane.
[0010] In a preferred embodiment, a secure forwarding path for data packets is configured at each topology node within the data plane, and intelligent traffic scheduling is performed on the secure forwarding path based on the real-time traffic situation of the topology control network. The process of updating the topology control network based on the newly allocated topology nodes includes: Each topology node of the topology control network is mapped to the corresponding sub-data plane based on the sub-control plane. A forwarding point for each data packet is created at the location of the sub-data plane. Data receiving terminals are deployed as receiving points for several forwarding points. Each forwarding point and receiving point is connected to construct a forwarding path. Set up a listening node and a protection node on each forwarding path, perform data security protection on the corresponding forwarding path, and use the forwarding path identifier that has completed data security protection as the secure forwarding path; Determine whether the real-time traffic of each topology node meets the traffic requirements for data forwarding of the corresponding topology node. If yes, no operation is performed. If no, intelligent traffic scheduling is performed on the secure forwarding path of the corresponding topology node. The traffic distribution of the topology control network that has not yet been added to the newly assigned topology node is used as the historical traffic situation. When a newly assigned topology node is added to the topology control network, the traffic distribution update of the newly generated topology control network is obtained as the real-time traffic situation.
[0011] In a preferred embodiment, the intelligent traffic scheduling process includes: Set up a public traffic pool, which consists of several traffic supply nodes; Assign traffic supply nodes to the corresponding secure forwarding paths, establish traffic supply areas between traffic supply nodes and secure forwarding paths, and record traffic request events corresponding to each traffic supply area. The event information corresponding to a traffic request event includes the event priority and request frequency; Connect the traffic supply area corresponding to the security forwarding path whose request frequency exceeds the preset frequency threshold to the public traffic pool and use it as a traffic relay area; connect the traffic supply area corresponding to the security forwarding path whose request frequency does not exceed the frequency threshold to the traffic relay area. When the traffic transfer area requests traffic resources from the public traffic pool, it directly schedules the sufficient traffic resources in the public traffic pool and releases the resources through the traffic supply nodes allocated on the secure forwarding path. In the traffic transfer area, the data packets to be forwarded are compiled based on the sufficient traffic resources. After compilation, the traffic resources are released and stored in the traffic transfer area as the corresponding standby traffic. When the corresponding traffic transfer area needs to forward data again, it directly requests the corresponding traffic resources from itself. When other traffic supply areas connected to the traffic relay area request traffic resources, they obtain the required traffic value based on their remaining traffic value, request the corresponding resources from the traffic relay area, and then execute the forwarding of their respective data packets.
[0012] In a preferred embodiment, establishing a gateway device synchronization network, and the process of collaborative operation and maintenance of industrial gateways with different protocols based on the gateway device synchronization network includes: Based on all gateway devices under the same industrial gateway, a corresponding gateway device network is constructed. Based on the device information of all gateway devices, an operation and maintenance set for the gateway device network is constructed. The operation and maintenance set includes the operation and maintenance procedures for each gateway device under different scenarios. A common operation and maintenance map is constructed based on operation and maintenance procedures under all scenarios. All operation instructions corresponding to each operation and maintenance procedure are used as a map item of the common operation and maintenance map. A map item is used to record the execution details of all procedures of an operation and maintenance procedure. Construct a gateway device network corresponding to all gateway devices belonging to other industrial gateways, and establish a data channel between other gateway device networks and the current gateway device network. Other gateway device networks traverse the map items corresponding to all their own gateway devices in the public operation and maintenance map through the data channel to construct their own industrial gateway operation and maintenance map and execute all operation and maintenance procedures represented by the operation and maintenance map.
[0013] This invention also provides a multi-protocol data security forwarding system for industrial gateways, the system comprising: The SDN processing module uses SDN network technology to build the control plane and data plane for operating industrial gateways, and performs corresponding visual configuration management for the control plane and data plane. The visualization topology module performs protocol-related processing on data packets from the industrial gateway at different times by the control plane, allocates a topology node corresponding to the data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; The data security forwarding module configures secure forwarding paths for data packets at each topology node within the data plane, and performs intelligent traffic scheduling for the secure forwarding paths based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. The device synchronization and maintenance module establishes a gateway device synchronization network and performs collaborative operation and maintenance on industrial gateways with different protocols based on the gateway device synchronization network.
[0014] In the above technical solution, the technical effects and advantages provided by the present invention are as follows: The present invention constructs a control plane and a data plane to perform protocol-related processing of data packets of industrial gateways at different time periods, assigns a corresponding topology node to each data packet, and constructs a real-time topology control network under the current control plane. In the data plane, it configures a secure forwarding path for data packets at each topology node, performs intelligent traffic scheduling on the secure forwarding path based on the real-time traffic situation of the topology control network, establishes a gateway device synchronization network, and performs collaborative operation and maintenance of industrial gateways with different protocols based on the gateway device synchronization network. This realizes secure and controllable data forwarding of multi-protocol industrial gateways and achieves centralized management of different industrial devices. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0016] Figure 1 This is a flowchart of a multi-protocol data security forwarding method for industrial gateways according to the present invention.
[0017] Figure 2 This is a schematic diagram of intelligent traffic scheduling in this invention.
[0018] Figure 3 This is a system block diagram of a multi-protocol data security forwarding system for industrial gateways according to the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Example 1, please refer to Figure 1 As shown in this embodiment, a multi-protocol data security forwarding method for industrial gateways includes the following steps: Step S1: Construct the control plane and data plane for operating the industrial gateway using SDN network technology, and perform corresponding visual configuration management for the control plane and data plane. Step S2: The control plane performs protocol-related processing on the data packets of the industrial gateway at different time periods, allocates a topology node corresponding to the data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; Step S3: Configure a secure forwarding path for data packets at each topology node in the data plane, and perform intelligent traffic scheduling on the secure forwarding path based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. Step S4: Establish a gateway device synchronization network and perform collaborative operation and maintenance on industrial gateways with different protocols based on the gateway device synchronization network.
[0021] It should be further explained that, in the specific implementation process, the process of constructing the control plane and data plane for operating the industrial gateway using SDN network technology, and performing corresponding visual configuration management for the control plane and data plane, includes: An SDN controller is deployed using SDN network technology. The SDN controller communicates with several industrial gateways, divides the communication coverage area corresponding to several industrial gateways, and creates a regional proxy interface for all industrial gateways in the same communication coverage area. Create a private authorized interface for each industrial gateway, and associate all private authorized interfaces under the same communication coverage area with the regional agent interface of that communication coverage area in sequence to establish an authentication path between the regional agent interface and the private authorized interface; Each regional agent interface imports a pre-defined decision management architecture set and a data forwarding architecture set; The decision management architecture set consists of several decision management sub-architectures, each of which is used to perform a certain type of control operation on the industrial gateway; The data forwarding architecture set consists of several data forwarding sub-architectures, each of which is used to perform a type of data forwarding operation on the industrial gateway; Several private authorized interfaces connected to the same regional agent interface obtain their respective decision management sub-architecture and data forwarding sub-architecture through authentication paths. The industrial gateway corresponding to each private authorized interface initializes two blank plane layers and arranges the decision management sub-architecture and data forwarding sub-architecture at different positions in the two blank plane layers, thereby constructing the sub-control plane and sub-data plane corresponding to each industrial gateway. Specifically, an authentication path is established between the regional proxy interface and the private authorization interface. The required decision management sub-architecture and data forwarding sub-architecture are obtained through this authentication path, as follows: Each industrial gateway's private authorized interface is pre-installed with a unique device digital certificate (as an identity credential), while the regional agent interface holds a server certificate issued by the private PKI root certificate. When establishing a connection, both parties perform bidirectional certificate authentication based on the TLS / DTLS protocol to authenticate the industrial gateway as a legitimate gateway and the SDN controller as a legitimate controller, which to some extent avoids unauthorized device access or man-in-the-middle attacks. After authentication, both parties determine a unique session master key through a forward security algorithm. Based on the session master key, they construct independent encryption keys and integrity verification keys for different services such as subsequent architecture transmission, control commands, and status reporting. Based on the encryption key, the control plane obfuscates and compresses the code of the decision management sub-architecture and the data forwarding sub-architecture, and uses the private key of the regional proxy interface to digitally sign the decision management sub-architecture and the data forwarding sub-architecture respectively, generating secure data packets corresponding to different architectures; The encrypted security data packet is transmitted to the private authorized interface of each industrial gateway through the established security channel. The industrial gateway first decrypts it using the session master key, and then verifies the digital signature using the public key preset on the control plane to verify that the architecture corresponding to the security data packet is trustworthy and has not been tampered with. Based on the integrity verification key, before loading the acquired decision management sub-architecture and data forwarding sub-architecture into the blank plane layer, the industrial gateway performs a secure hash calculation on the architecture code and compares the measurement results with the expected values issued by the control plane. Only after the verification is passed can loading and initialization be allowed in the protected container or security zone to prevent malicious code injection.
[0022] All sub-control planes and sub-data planes are arranged based on their distribution locations in the deployment area, thereby constructing the final control plane and data plane for operating all industrial gateways. The control plane is used for decision management of the industrial gateways, and the data plane is used for forwarding relevant data from the industrial gateways. Several visual drag points are set on the control plane, and a corresponding interactive container is set for each visual drag point. When a visual drag point is clicked, devices related to the industrial gateway can be added, deleted, or moved within the interactive container corresponding to the visual drag point. Each visual drag point corresponds to a sub-control plane; Each interactive container records the parameter configuration of the industrial gateway after the corresponding visual drag-and-drop point is clicked, and synchronizes the parameter configuration to other interactive containers for configuration synchronization of other industrial gateways; The data plane is divided based on the sub-data plane to obtain several visualization management points. The sub-data plane is aligned with the sub-control plane to establish data communication between the visualization management points and the visualization drag points. When the data plane forwards relevant data to each industrial gateway, it counts the real-time traffic of each industrial gateway and incorporates the real-time traffic into its respective interaction container on the control plane. Different interaction containers then synchronize the traffic changes among several industrial gateways.
[0023] It should be further explained that, in the specific implementation process, the process by which the control plane performs protocol-related processing on data packets from the industrial gateway at different times includes: Each industrial gateway encapsulates all the data it needs to transmit into a separate data packet and labels the data packet with the gateway address of its respective industrial gateway. The gateway address serves as the unique identifier of the industrial gateway. Based on the preset time window corresponding to the time period when the data packet is encapsulated, the data packets at the corresponding locations of all industrial gateways on the control plane are sliced according to the time window, each data packet is processed into several time-series slice data, and the time-series slice data under the same time window are integrated into a data queue. The first time-series slice data in each data queue is used as the source target. The corresponding data transmission protocol is set for the source target. The second to last time-series slice data in the data queue are used as the linkage target. Establish a message component between each linked target and the source target. Compile the data transmission protocol corresponding to the source target into the message content of the corresponding message component. Store the original message content in the message component of the source target. Use the component address of the message component of each linked target as the message index to obtain the original. When the linked targets need to perform their respective data transmission, obtain the compilation result of the message content corresponding to the original based on the message index, and then complete their respective data transmission.
[0024] It should be further explained that, in the specific implementation process, the process of allocating a topology node corresponding to a data packet on the control plane and constructing a real-time topology control network under the current control plane based on the topology node includes: Based on the control subplane where each industrial gateway is located on the control plane, create network access requests for data packets corresponding to each industrial gateway, set up several network nodes, and allocate a certain amount of network resources to each network node. Determine whether each network access request is compatible with the network resources of all network nodes in the adjacent ring position. If so, associate the obtained network node with the data packet that initiated the network reception request, store the data packet in the corresponding network node, and identify the network node as a topology node and assign it to the control plane. If not, select a number of idle network nodes in the adjacent ring position, establish all resource release paths between all network nodes, select one network node as the resource bearing target, transfer the remaining network resources of other network nodes after they have maintained their own operation to the resource bearing target through the resource release path, use the resource bearing target as the associated object of the data packet corresponding to the current network access request, store the data packet to the resource bearing target, identify the network node corresponding to the resource bearing target as a topology node and assign it to the control plane; After each data packet has completed its corresponding allocation to a topology node on the control plane, a topology path is constructed between topology nodes at each adjacent location to connect topology nodes at different locations, thus constructing the corresponding topology control network. Whenever a new topology node is generated and allocated to the control plane, a topology path is established between the new topology node and the existing topology control network as an update, thus obtaining the real-time topology control network under the current control plane.
[0025] It should be further explained that, in the specific implementation process, configuring secure forwarding paths for data packets at each topology node within the data plane, and intelligently scheduling traffic for these secure forwarding paths based on the real-time traffic situation of the topology control network, the process of updating the topology control network based on the newly allocated topology nodes includes: Each topology node in the topology control network is mapped to the corresponding sub-data plane on the data plane based on its respective sub-control plane, and a forwarding point for its respective data packets is created at the location of the sub-data plane. Deploy data receiving terminals as receiving points for several data packets corresponding to forwarding points. Connect each forwarding point to the receiving point to construct its own forwarding path. Set up listening nodes and protection nodes on each forwarding path to perform data security protection on the corresponding forwarding path. Use the forwarding path identifier that has completed data security protection as the secure forwarding path. The monitoring nodes are used to obtain abnormal events corresponding to each forwarding path, while the protection nodes are used to handle these abnormal events. The monitoring nodes are deployed on the forwarding paths and are responsible for monitoring data packets flowing through those paths to detect abnormal events. Specific functions include: traffic monitoring, used to monitor data packet traffic on the forwarding path in real time, including the number of data packets, the number of bytes, and the distribution of data packet sizes, recording traffic time-series data for traffic pattern analysis; and protocol compliance checking, for known industry protocols (such as Modbus, OPC). (UA, etc.) Checks whether data packets conform to protocol specifications, such as checking the format of Modbus TCP requests and responses and whether function codes are valid; detects abnormal behavior: based on predefined rules or machine learning models, it detects abnormal behavior, such as function codes that have never appeared before, abnormally frequent read and write requests, and data access outside of working hours; it detects signs of network attacks, such as scanning (massive connection attempts), DoS attacks (traffic flooding), and injection attacks (malformed data packets); collects performance metrics such as latency, jitter, and packet loss rate on the forwarding path to assess the health of the forwarding path; logs and reports detected events (normal and abnormal) and reports the logs to the log server deployed on the control plane. When a serious anomaly is detected, it immediately sends an alarm to the control plane and protection nodes.
[0026] Protection nodes are also deployed on the secure forwarding path, responsible for responding to abnormal events detected by the monitoring nodes to ensure data forwarding security. Specific functions include: access control, filtering data packets according to preset security policies, such as whitelist-based access control, allowing only specific source / destination IPs, ports, and protocols to pass, and dynamically updating access control rules to cope with new types of attacks; traffic shaping and rate limiting, shaping abnormal traffic, such as limiting the sending rate of a certain source IP to prevent bandwidth abuse, and buffering sudden traffic to smooth traffic and avoid congestion; packet cleaning and correction, cleaning malicious data packets, such as removing malicious payloads or correcting protocol fields, and discarding malicious data packets that cannot be cleaned; encryption and decryption, encrypting data packets for transmission on links requiring encryption to prevent eavesdropping and tampering, decrypting data packets at the receiving end, and then passing them to the application; and intrusion prevention, blocking attack traffic in real time, such as activating defense mechanisms or directly blocking the attack source when a DoS attack is detected. By deploying monitoring and protection nodes, the secure forwarding path can not only forward data, but also monitor and defend against security threats in real time, thereby achieving intelligent and adaptive security protection.
[0027] Obtain the real-time traffic at each topology node in the topology control network, and determine whether the real-time traffic of each topology node meets the traffic requirements for data forwarding of the corresponding topology node. If yes, no operation is performed; otherwise, intelligent traffic scheduling is performed on the secure forwarding path of the corresponding topology node.
[0028] like Figure 2 As shown, the process of intelligent traffic scheduling is as follows: Set up a public traffic pool, which consists of several traffic supply nodes; Assign traffic supply nodes to the corresponding secure forwarding paths, establish traffic supply areas between traffic supply nodes and secure forwarding paths, and record traffic request events corresponding to each traffic supply area. The event information corresponding to a traffic request event includes the event priority and request frequency; Among them, the event priority is used to define the priority of the corresponding traffic supply area in requesting traffic resources. The higher the event priority, the higher the priority of the corresponding request. The request frequency is the number of times the corresponding traffic supply area initiates resource requests to the public traffic pool in a preset period. The higher the number, the more times the corresponding traffic supply area will experience traffic shortage. Connect the traffic supply area corresponding to the security forwarding path whose request frequency exceeds the preset frequency threshold to the public traffic pool and use it as a traffic relay area; connect the traffic supply area corresponding to the security forwarding path whose request frequency does not exceed the frequency threshold to the traffic relay area. When the traffic transfer area requests traffic resources from the public traffic pool, it directly schedules the sufficient traffic resources in the public traffic pool and releases the resources through the traffic supply nodes allocated on the secure forwarding path. In the traffic transfer area, the data packets to be forwarded are compiled based on the sufficient traffic resources. Among them, the resource value of sufficient traffic resources is greater than or equal to the traffic required for data forwarding by the topology node corresponding to the secure forwarding path.
[0029] After compilation, the traffic resources are released and stored in the traffic transfer area as the corresponding standby traffic. When the corresponding traffic transfer area needs to forward data again, it directly requests the corresponding traffic resources from itself. When other traffic supply areas connected to the traffic relay area request traffic resources, they obtain the required traffic value based on their remaining traffic value, request the corresponding resources from the traffic relay area, and then execute the forwarding of their respective data packets.
[0030] It should be noted that the traffic transfer area is directly connected to the public traffic pool. At the same time, the traffic transfer area is a request area with frequent traffic shortages. After the traffic resources requested in the traffic transfer area are compiled, they are stored in its own location for easy use in the future. This avoids the computational overhead caused by frequently requesting traffic resources from the public traffic pool and also improves the efficiency of resource utilization to a certain extent. Other traffic supply areas with request frequencies that do not exceed the frequency threshold can meet their own traffic needs in most cases. When there is a shortage, the corresponding traffic resources are supplemented from the traffic transfer area, which also speeds up the acquisition efficiency of traffic resources.
[0031] The traffic distribution of the topology control network that has not yet been added to the newly assigned topology node is used as the historical traffic situation. When a newly assigned topology node is added to the topology control network, the traffic distribution update of the newly generated topology control network is obtained as the real-time traffic situation.
[0032] It should be further explained that, in the specific implementation process, the process of establishing a gateway device synchronization network and performing collaborative operation and maintenance on industrial gateways using different protocols based on the gateway device synchronization network includes: Based on all gateway devices under the same industrial gateway, a corresponding gateway device network is constructed. The gateway device network is used to perform operation and maintenance on all gateway devices under the corresponding industrial gateway. Based on the device information of all gateway devices under the gateway device network, the operation and maintenance operation set of the gateway device network is constructed. The operation and maintenance operation set includes the operation and maintenance procedures for each gateway device under different scenarios; A common operation and maintenance map is constructed based on the operation and maintenance procedures under all current scenarios. All operation instructions corresponding to each operation and maintenance procedure are used as a map item of the common operation and maintenance map. A map item is used to record the execution details of all procedures corresponding to a certain operation and maintenance procedure. Construct a gateway device network corresponding to all gateway devices belonging to other industrial gateways, and establish a data channel between the other gateway device network and the current gateway device network. Through the data channel, the other gateway device networks traverse the map items that correspond to the device information of all their own gateway devices in the public operation and maintenance map. The operation and maintenance map corresponding to their respective industrial gateways is constructed from all the adapted map items. All operation and maintenance procedures represented by the operation and maintenance map are executed, thereby completing the collaborative operation and maintenance of gateway devices under industrial gateways with different protocols.
[0033] Example 2, please refer to Figure 3 As shown in this embodiment, a multi-protocol data security forwarding system for industrial gateways includes: The SDN processing module uses SDN network technology to build the control plane and data plane for operating industrial gateways, and performs corresponding visual configuration management for the control plane and data plane. The visualization topology module performs protocol-related processing on data packets from the industrial gateway at different times by the control plane, allocates a topology node corresponding to a data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; The data security forwarding module configures secure forwarding paths for data packets at each topology node within the data plane, and performs intelligent traffic scheduling for the secure forwarding paths based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. The device synchronization and maintenance module establishes a gateway device synchronization network and performs collaborative operation and maintenance on industrial gateways with different protocols based on the gateway device synchronization network.
[0034] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for secure forwarding of multi-protocol data for industrial gateways, characterized in that, Includes the following steps: Step S1: Construct the control plane and data plane for operating the industrial gateway using SDN network technology, and perform corresponding visual configuration management for the control plane and data plane. Step S2: The control plane performs protocol-related processing on the data packets of the industrial gateway at different time periods, allocates a topology node corresponding to the data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; Step S3: Configure a secure forwarding path for data packets at each topology node in the data plane, and perform intelligent traffic scheduling on the secure forwarding path based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. Step S4: Establish a gateway device synchronization network, and perform collaborative operation and maintenance on industrial gateways using different protocols based on the gateway device synchronization network, including: Based on all gateway devices under the same industrial gateway, a corresponding gateway device network is constructed. Based on the device information of all gateway devices, an operation and maintenance set for the gateway device network is constructed. The operation and maintenance set includes the operation and maintenance procedures for each gateway device under different scenarios. A common operation and maintenance map is constructed based on operation and maintenance procedures under all scenarios. All operation instructions corresponding to each operation and maintenance procedure are used as a map item of the common operation and maintenance map. A map item is used to record the execution details of all procedures of an operation and maintenance procedure. Construct a gateway device network corresponding to all gateway devices belonging to other industrial gateways, and establish a data channel between other gateway device networks and the current gateway device network. Other gateway device networks traverse the map items corresponding to all their own gateway devices in the public operation and maintenance map through the data channel to construct their own industrial gateway operation and maintenance map and execute all operation and maintenance procedures represented by the operation and maintenance map.
2. The multi-protocol data security forwarding method for industrial gateways according to claim 1, characterized in that, The process of constructing the control plane and data plane for operating industrial gateways using SDN network technology includes: An SDN controller is deployed using SDN network technology. The SDN controller communicates with several industrial gateways, divides the communication coverage area corresponding to several industrial gateways, and sets up regional proxy interfaces. Create a private authorized interface for each industrial gateway, establish an authentication path between the regional agent interface and the private authorized interface under the same communication coverage area, and connect several private authorized interfaces to the same regional agent interface; Each sub-architecture for decision management and data forwarding is obtained through the authentication path, and corresponding sub-control planes and sub-data planes are constructed respectively. All sub-control planes and sub-data planes are arranged according to their distribution locations in the deployment area to construct control planes and data planes for operating all industrial gateways.
3. The multi-protocol data security forwarding method for industrial gateways according to claim 2, characterized in that, The process of performing corresponding visual configuration management for the control plane and data plane includes: Several visual drag points and corresponding interactive containers are set on the control plane. Within the interactive containers, devices related to the industrial gateway can be added, deleted, and moved. Each visual drag point corresponds to a sub-control plane. Each interactive container records the parameter configuration of its own industrial gateway and synchronizes it to other interactive containers for configuration synchronization of other industrial gateways; The data plane is divided based on the sub-data plane to obtain several visualization management points. The sub-data plane and the sub-control plane are aligned in position to establish data communication between the visualization management points and the visualization drag points. When forwarding data for each industrial gateway, the real-time traffic of each industrial gateway is counted and included in its respective interaction container in the control plane. Different interaction containers synchronize the traffic changes between several industrial gateways.
4. A multi-protocol data security forwarding method for industrial gateways according to claim 3, characterized in that, The process by which the control plane performs protocol-related processing on data packets from the industrial gateway at different times includes: All data that each industrial gateway needs to transmit is encapsulated into a single data packet; Based on the time window of the data packet encapsulation period, the data packet is sliced according to the time window and processed into several time-series slice data. The time-series slice data under the same time window are integrated into a data queue. Set the source target and linked target in each data queue, establish a message component between the linked target and the source target, and complete the data packet protocol-related processing based on the message component to complete the corresponding data transmission.
5. A multi-protocol data security forwarding method for industrial gateways according to claim 4, characterized in that, The process of allocating a topology node corresponding to a data packet on the control plane and constructing a real-time topology control network under the current control plane based on the topology node includes: Create a network access request for a data packet, set up several network nodes, allocate a certain amount of network resources to each network node, and determine whether each network access request is compatible with the network resources of all network nodes in the adjacent ring position. The decision on whether to identify the corresponding network node as a topology node is based on the judgment result. After each data packet has completed its allocation to the topology nodes on the control plane, a topology path is constructed between the topology nodes at each adjacent location to connect the topology nodes at different locations, thus constructing the topology control network. Whenever a new topology node is generated and assigned to the control plane, a topology path is established between the new topology node and the existing topology control network and used as an update to obtain the real-time topology control network under the current control plane.
6. A multi-protocol data security forwarding method for industrial gateways according to claim 5, characterized in that, Within the data plane, secure forwarding paths for data packets are configured at each topology node. Based on the real-time traffic conditions of the topology control network, intelligent traffic scheduling is performed on these secure forwarding paths. The process of updating the topology control network based on the newly allocated topology nodes includes: Each topology node of the topology control network is mapped to the corresponding sub-data plane based on the sub-control plane. A forwarding point for each data packet is created at the location of the sub-data plane. Data receiving terminals are deployed as receiving points for several forwarding points. Each forwarding point and receiving point is connected to construct a forwarding path. Set up a listening node and a protection node on each forwarding path, perform data security protection on the corresponding forwarding path, and use the forwarding path identifier that has completed data security protection as the secure forwarding path; Determine whether the real-time traffic of each topology node meets the traffic requirements for data forwarding of the corresponding topology node. If yes, no operation is performed; otherwise, intelligent traffic scheduling is performed on the secure forwarding path of the corresponding topology node. The traffic distribution of the topology control network that has not yet been added to the newly assigned topology node is used as the historical traffic situation. When a newly assigned topology node is added to the topology control network, the traffic distribution update of the newly generated topology control network is obtained as the real-time traffic situation.
7. A multi-protocol data security forwarding method for industrial gateways according to claim 6, characterized in that, The process of intelligent traffic scheduling includes: Set up a public traffic pool, which consists of several traffic supply nodes; Assign traffic supply nodes to the corresponding secure forwarding paths, establish traffic supply areas between traffic supply nodes and secure forwarding paths, and record traffic request events corresponding to each traffic supply area. The event information corresponding to a traffic request event includes the event priority and request frequency; Connect the traffic supply area corresponding to the security forwarding path whose request frequency exceeds the preset frequency threshold to the public traffic pool and use it as a traffic relay area; connect the traffic supply area corresponding to the security forwarding path whose request frequency does not exceed the frequency threshold to the traffic relay area. When the traffic transfer area requests traffic resources from the public traffic pool, it directly schedules the sufficient traffic resources in the public traffic pool and releases the resources through the traffic supply nodes allocated on the secure forwarding path. In the traffic transfer area, the data packets to be forwarded are compiled based on the sufficient traffic resources. After compilation, the traffic resources are released and stored in the traffic transfer area as the corresponding standby traffic. When the corresponding traffic transfer area needs to forward data again, it directly requests the corresponding traffic resources from itself. When other traffic supply areas connected to the traffic relay area request traffic resources, they obtain the required traffic value based on their remaining traffic value, request the corresponding resources from the traffic relay area, and then execute the forwarding of their respective data packets.
8. A multi-protocol data security forwarding system for industrial gateways, used to implement the multi-protocol data security forwarding method according to any one of claims 1-7, characterized in that, The system includes: The SDN processing module uses SDN network technology to build the control plane and data plane for operating industrial gateways, and performs corresponding visual configuration management for the control plane and data plane. The visualization topology module performs protocol-related processing on data packets from the industrial gateway at different times by the control plane, allocates a topology node corresponding to the data packet on the control plane, and constructs a real-time topology control network under the current control plane based on the topology node; The data security forwarding module configures secure forwarding paths for data packets at each topology node within the data plane, and performs intelligent traffic scheduling for the secure forwarding paths based on the real-time traffic situation of the topology control network. The real-time traffic situation is obtained by updating the topology control network based on the newly allocated topology nodes. The device synchronization and maintenance module establishes a gateway device synchronization network and performs collaborative operation and maintenance on industrial gateways with different protocols based on the gateway device synchronization network.